Quantum Audit Logo

Is AntFun Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

AntFun ANTFUN
0x6ced…087c
BNB Chain
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked 7d ago 1 audit on record
Executive SummaryAI Copilot

The ANTFUNOFT contract implements an Omnichain Fungible Token (OFT) using LayerZero, enhanced with EIP-3009 for gasless meta-transactions. The contract leverages well-audited OpenZeppelin libraries for access control (Ownable) and cryptographic utilities (EIP712, ECDSA). The implementation of EIP-3009 includes robust nonce management and timestamp checks to prevent replay attacks and ensure authorization validity. Key areas of focus include centralized ownership, reliance on external protocols, and inherent characteristics of meta-transactions and blockchain timestamps. No critical or high-severity vulnerabilities were identified.

2 Low2 Informational
Volume 24h
$299.1K
Liquidity
$2.43M
Price
$0.08971
Token Age
3mo
Top 10 Holders
62.0%

Security Findings

Low

Timestamp Dependence for Authorization Validity

L-01The EIP-3009 authorization mechanism relies on `block.timestamp` to enforce `validAfter` and `validBefore` conditions. While standard for time-based checks on EVM chains, `block.timestamp` can be manipulated by miners within a small window (e.g., up to 900 seconds on Ethereum). This could lead to minor deviations in the precise validity period of an authorization, potentially allowing a transaction to be valid slightly earlier or later than intended by the signer.
IssueThe EIP-3009 authorization mechanism relies on `block.timestamp` to enforce `validAfter` and `validBefore` conditions. While standard for time-based checks on EVM chains, `block.timestamp` can be manipulated by miners within a small window (e.g., up to 900 seconds on Ethereum). This could lead to minor deviations in the precise validity period of an authorization, potentially allowing a transaction to be valid slightly earlier or later than intended by the signer.
FixWhile this is an inherent characteristic of blockchain timestamps and not a flaw in the EIP-3009 implementation, users should be aware of this potential imprecision. When signing authorizations, consider adding a small buffer to `validAfter` and `validBefore` if precise timing is critical, or use a sufficiently wide window where minor deviations are acceptable.
StatusUnresolved
Low

Front-running Risk for EIP-3009 Authorizations

L-02EIP-3009 meta-transactions, by their nature, are susceptible to front-running. If a signed authorization is broadcast to the mempool, a malicious actor could observe it and submit a transaction with a higher gas price to execute the same authorization (or cancel it) before the legitimate sender. Although nonces prevent replay attacks, a successful front-run would consume the nonce, forcing the original sender to generate a new signature, leading to a poor user experience.
IssueEIP-3009 meta-transactions, by their nature, are susceptible to front-running. If a signed authorization is broadcast to the mempool, a malicious actor could observe it and submit a transaction with a higher gas price to execute the same authorization (or cancel it) before the legitimate sender. Although nonces prevent replay attacks, a successful front-run would consume the nonce, forcing the original sender to generate a new signature, leading to a poor user experience.
FixAdvise users to keep the `validBefore` window as short as practically possible to minimize the time an authorization is exposed to the mempool. Implement off-chain mechanisms to submit transactions quickly or use private transaction relays where available to reduce front-running opportunities.
StatusUnresolved
Info

Centralized Ownership and Control

I-01The contract utilizes OpenZeppelin's `Ownable` pattern, which assigns all administrative privileges to a single owner address. This includes the ability to set LayerZero delegate and minimum destination gas parameters (inherited from OFT). This centralization of power, while common, introduces a single point of failure and potential for a single compromised key to control critical contract functions.
IssueThe contract utilizes OpenZeppelin's `Ownable` pattern, which assigns all administrative privileges to a single owner address. This includes the ability to set LayerZero delegate and minimum destination gas parameters (inherited from OFT). This centralization of power, while common, introduces a single point of failure and potential for a single compromised key to control critical contract functions.
FixConsider migrating ownership to a multi-signature wallet (e.g., Gnosis Safe) to distribute control and enhance security against a single point of compromise. This would require multiple approvals for sensitive operations.
StatusUnresolved
Info

Reliance on LayerZero Protocol Security

I-02The contract's core cross-chain functionality is built upon LayerZero's Omnichain Fungible Token (OFT) standard. This means the security and operational integrity of the ANTFUNOFT token across different chains are inherently dependent on the LayerZero protocol, its endpoints, and its underlying infrastructure. Any vulnerabilities or operational issues within LayerZero could directly impact the token.
IssueThe contract's core cross-chain functionality is built upon LayerZero's Omnichain Fungible Token (OFT) standard. This means the security and operational integrity of the ANTFUNOFT token across different chains are inherently dependent on the LayerZero protocol, its endpoints, and its underlying infrastructure. Any vulnerabilities or operational issues within LayerZero could directly impact the token.
FixMaintain awareness of LayerZero's security posture, audits, and any reported vulnerabilities. Ensure that the LayerZero endpoint address used is the official and correct one for the deployed network.
StatusUnresolved

Category Ratings

TechnicalMedium6/10

The contract demonstrates good technical architecture (7.1 Architecture) by inheriting from established and audited libraries like OpenZeppelin's Ownable, EIP712, and ECDSA, as well as LayerZero's OFT. Code security (7.2 Code Security) is strong, with EIP-3009 implementation correctly using nonces and signature verification to prevent replay attacks. Access control (7.3 Access Control) is managed via Ownable, centralizing administrative functions. The use of assembly for signature parsing is efficient but requires careful review, which appears correctly implemented here. No reentrancy or integer overflow/underflow issues were found due to Solidity 0.8.x and OpenZeppelin's safe math.

GovernanceHigh2/10

The economic model (7.4 Economic) is that of a standard fungible token with cross-chain capabilities and gasless transfers. Governance (7.5 Governance) is centralized, with a single owner address controlling administrative functions, including the LayerZero delegate. This concentration of power is a design choice, not a vulnerability, but it introduces a single point of failure. External dependencies (7.6 External) on LayerZero's OFT protocol mean the contract's cross-chain functionality is reliant on the security and operational integrity of LayerZero itself.

UpgradesHigh3/10

The contract is not designed with an explicit upgrade mechanism (7.7 Upgrades). While a 'version' constant is present, there are no proxy patterns (e.g., UUPS, Transparent) or other upgradeability features implemented. This means the contract is immutable once deployed, which eliminates upgrade-related risks but also prevents future modifications without a new deployment. Operations (7.8 Operations) are straightforward, with the owner managing basic administrative tasks.

Security Checklist

Contract VerifiedPass
Ownership RenouncedFail
No Mint FunctionFail
Liquidity LockedFail
Not a ProxyPass
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Holder Composition

30.9% in wallets31.1% in contracts
Effective Concentration43.3%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder100.0%
Top-3 Unlocked100.0%

Key Addresses

Deployer
0x44a9…dadb
Unlocked LP Held By
0x3ef9…5bc90x959e…38a40x36ba…8af10x3b46…b3750x12e3…eb970x5ad1…2cb00x3443…10b60xa654…1ecd0xb262…eeed0x2ffc…8e89

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Ownership NOT renounced — owner is an EOA (single private key)
  • Mintable supply — no cap found, dilution unbounded
  • Top-10 concentration > 30% (62.0% total → 43.3% effective; 30.9% in EOAs, 31.1% in contracts — moderate)
  • Liquidity not locked, but no owner/deployer address holds LP — market-depth risk, not rug risk
  • LP top1 unlocked holder = 100.0% (independent LP — depth risk, pool = 98% of DEX liquidity)
  • LP top3 unlocked holders = 100.0% (independent LP — depth risk, pool = 98% of DEX liquidity)
  • 2 Low finding(s) from audit

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Billions Network Token (BILL)High RiskHemiHigh RiskQuack AI Token (Q)High RiskHoloworld AI (HOLO)High RiskPowerHigh RiskCreoEngine (CREO)High Risk

Would You Like a More Detailed Audit of AntFun?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit